Identify the core features and objects of Microsoft 365 services
Zero Trust and Defender XDR
Apply foundational Zero Trust reasoning and recognize how Defender XDR unifies cross-workload detection and response.
What you need to know
- Zero Trust uses three principles: verify explicitly, use least privilege, and assume breach.
- Authentication establishes identity; authorization decides what an authenticated principal may do.
- Threat intelligence provides context about adversaries and indicators; threat protection uses signals and controls to prevent, detect, investigate, and respond.
- Defender XDR correlates alerts across supported identity, endpoint, email, app, and cloud workloads into incidents.
Objects and administrative surfaces
- Incidents, alerts, advanced hunting, and automated investigation — Microsoft Defender portal.
- Identity and access policy — Microsoft Entra admin center.
How it works
- Defender XDR correlation helps analysts see a connected attack story instead of investigating isolated alerts.
- Assume breach means limit blast radius and continuously monitor; it does not mean abandon prevention.
When to use it
- Use Defender XDR to investigate a correlated incident and threat intelligence to enrich what an indicator or actor means.
- Use Conditional Access or resource permissions for access enforcement, not Defender incident records.
Security and governance implications
- Grant analysts only the roles needed for investigation and response.
- Pair prevention and access controls with monitoring and response evidence.
Troubleshooting signals
- Start from the incident timeline, affected entities, and correlated alerts.
- Confirm the relevant Defender workload is onboarded and producing signals.
Exam traps
- MFA is an authentication control, not an authorization rule.
- Defender XDR is not the place to assign Microsoft 365 product licenses or SharePoint permissions.
Key takeaways
- Verify explicitly; use least privilege; assume breach.
- Defender XDR joins related signals into incidents for coordinated investigation.
Related objectives
- D1.2.a
- D1.2.b
- D1.2.c
- D1.2.d
- D1.2.e